US seizes domains linked to China's Flax Typhoon hackers, disrupts two cyber tools

Share:
Audio Loading voice…
US seizes domains linked to China's Flax Typhoon hackers, disrupts two cyber tools

Synopsis

The US Justice Department and FBI have seized seven internet domains tied to China's Flax Typhoon group, shutting down two hacking tools — Microscan and FishHub — that targeted power grids, airports, and universities across the US, Japan, Poland, and Taiwan. It is the second takedown of the same contractor network in just over a year, and Washington's message is unambiguous: Beijing's contractor-driven cyber model will face sustained disruption.

Key Takeaways

The US Justice Department and FBI seized 7 internet domains on 8 October 2026 linked to Flax Typhoon , a Chinese state-sponsored hacking group.
Two tools were disrupted: Microscan (vulnerability scanning via a Mirai botnet) and FishHub (spear-phishing for remote access and data theft).
Confirmed targets include a South Carolina power company , airports in Japan and Poland , Taiwanese energy firms , and approximately 20 Taiwanese universities .
The tools were allegedly operated by Integrity Technology Group , a China-based firm with Chinese government contracts.
This is the second US disruption of Integrity Tech's infrastructure; the first, in September 2024 , took down a botnet of over 200,000 devices .
Assistant Attorney General John A.
Eisenberg vowed the US would not allow China to act 'with impunity in cyberspace.'

The US Justice Department and the FBI have seized internet domains used by suspected Chinese state-sponsored hackers to target critical infrastructure and computer networks across the United States and abroad, disrupting two cyber tools — Microscan and FishHub — used for vulnerability scanning and targeted attacks. The operation, announced on Thursday, 8 October 2026, was authorised by a federal court in Pennsylvania and marks the second publicly confirmed US disruption of the same hacking network.

The Operation and Its Targets

The seized domains were linked to Integrity Technology Group, a China-based company with government contracts, allegedly operating as a contractor for Flax Typhoon — a Chinese state-sponsored cyber group that US authorities have associated with attacks on government, commercial, and critical infrastructure networks worldwide. A seizure warrant issued on 6 October by US Magistrate Judge Maureen P. Kelly in the Western District of Pennsylvania authorised the seizure of seven domain names.

Targets of the hacking operation reportedly included a power company in South Carolina, a multinational non-governmental organisation, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and two universities in Taiwan.

How the Two Tools Worked

According to court documents, Microscan was developed by Integrity Tech to identify vulnerabilities in computer systems that could subsequently be exploited by its clients. The company allegedly deployed a botnet — comprising internet-connected devices infected with a variant of Mirai malware — to conduct large-scale scanning operations, with hackers accessing the tool through one of the seized domains.

The second tool, FishHub, was allegedly used in spear-phishing attacks designed to compromise targeted networks. Once initial access was obtained, FishHub could download additional malicious software enabling unauthorised remote access or extract specific files and transmit them to servers controlled by Integrity Tech. Approximately 20 Taiwanese universities were confirmed as victims of FishHub-related activity, according to the Justice Department.

What US Officials Said

Assistant Attorney General for National Security John A. Eisenberg issued a pointed warning: 'The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace.' He said the Justice Department would continue using its investigative and enforcement powers to disrupt the group's operations.

US Attorney Troy Rivetti for the Western District of Pennsylvania said the operation demonstrated Washington's determination to disrupt Chinese-linked cyber activity. 'These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities,' Rivetti said.

FBI Cyber Division Assistant Director Brett Leatherman emphasised the contractor model Beijing allegedly uses to scale its operations. 'The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity,' he said.

Background and Pattern

This is the second publicly announced US disruption of Integrity Tech's cyber infrastructure. In September 2024, the Justice Department announced the takedown of a Mirai malware botnet associated with the same company, which had compromised more than 200,000 consumer devices in the United States and other countries. The recurrence underscores what US officials describe as a persistent, contractor-driven Chinese cyber campaign that adapts and reconstitutes after each disruption.

This comes amid an intensifying pattern of US-China friction in cyberspace, with federal agencies having previously attributed multiple infrastructure intrusions — including attacks on telecoms and water utilities — to Beijing-linked actors. Analysts note that targeting civilian infrastructure such as airports, power companies, and universities signals an intelligence-gathering and pre-positioning strategy rather than purely destructive intent.

What Comes Next

The Justice Department has indicated it will continue enforcement actions against entities supporting Chinese state cyber operations. The seizures neutralise the specific domain infrastructure used by Microscan and FishHub, but investigators have not disclosed whether arrests or indictments are forthcoming. Governments in Japan, Poland, and Taiwan — whose infrastructure was among the confirmed targets — are expected to be briefed by US counterparts.

Point of View

Disrupted first in 2024 and now again in 2026 — exposes a structural flaw in the US response: domain seizures and botnet takedowns neutralise specific infrastructure but leave the underlying contractor ecosystem intact. Beijing's outsourcing model is deliberately designed for resilience; a contractor absorbs the legal and reputational blow while the state-level capability reconstitutes. The inclusion of civilian targets — airports, universities, NGOs — alongside power utilities also signals a broader intelligence pre-positioning campaign, not just espionage. What remains publicly unanswered is whether Washington is prepared to move beyond disruption to deterrence: indictments, sanctions on Integrity Tech's executives, or coordinated allied response. Without that escalation ladder, each takedown risks becoming a PR win that the adversary simply rebuilds around.
NationPress
9 Oct 2026

Frequently Asked Questions

What are Microscan and FishHub, the tools seized by the FBI?
Microscan is a vulnerability-scanning tool allegedly developed by Integrity Technology Group, using a Mirai malware botnet of internet-connected devices to identify weaknesses in target systems. FishHub is a spear-phishing tool used to gain initial access to networks, after which it could install malware for remote control or steal files.
Who is Flax Typhoon and what is its connection to the Chinese government?
Flax Typhoon is a Chinese state-sponsored cyber group that US authorities have linked to attacks on government, commercial, and critical infrastructure networks globally. It is allegedly supported by Integrity Technology Group, a China-based contractor with Chinese government contracts.
Which countries and organisations were targeted in this hacking campaign?
Confirmed targets include a power company in South Carolina, airports in Japan and Poland, Taiwanese natural gas and electricity companies, a multinational NGO, and approximately 22 universities — two in Taiwan confirmed via Microscan and around 20 via FishHub.
How is this different from the 2024 disruption of the same group?
The September 2024 action targeted a Mirai malware botnet operated by Integrity Technology Group that had compromised more than 200,000 consumer devices. The October 2026 operation specifically seized the domain infrastructure underpinning Microscan and FishHub, two distinct offensive tools used for scanning and phishing attacks.
What happens after the domain seizures — will there be arrests?
The Justice Department has not disclosed whether arrests or indictments are forthcoming. The seizures block the specific domains used to operate the two tools, but officials have only said enforcement actions against entities supporting Chinese state cyber operations will continue.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 3 months ago
  4. 3 months ago
  5. 3 months ago
  6. 4 months ago
  7. 5 months ago
  8. 6 months ago
Google Prefer NP
On Google